# States Face Critical Cybersecurity Crisis as Federal Funding Dries Up: Congressional Testimony Reveals Growing Threat Gap


State governments are increasingly vulnerable to sophisticated cyberattacks as federal support erodes and budget constraints squeeze their ability to defend critical infrastructure. During a recent House Homeland Security Subcommittee hearing, security leaders from Tennessee, Florida, and New York delivered urgent testimony, warning Congress that without immediate restoration of federal funding and partnership, state and local governments will struggle to protect their citizens and essential services.


The hearing, titled "State and Local Cybersecurity: Escalating Threats, Federal Partnership, and the Resilience of America's Communities," highlighted a growing paradox: at a time when states face relentless attacks from sophisticated threat actors and ransomware gangs, they are receiving less federal support than ever before. This crisis threatens not only state government operations but also the cybersecurity posture of the communities they serve.


## The Threat Environment: Growing Sophistication, Growing Extortion


States are not facing amateur attackers. Modern threat actors have professionalized their operations, deploying advanced attack tools and coordinated campaigns against state infrastructure. Ransomware gangs, in particular, have become increasingly brazen—they demand exorbitant payments, and more concerning, they follow through on threats to leak stolen data when victims refuse to pay.


Key threat indicators:

  • Sophisticated tooling: Threat actors now have access to advanced attack frameworks and services designed specifically to compromise government networks
  • Coordinated campaigns: Ransomware operations are increasingly targeting multiple organizations simultaneously, suggesting centralized command structures
  • Data extortion pressure: Gangs no longer rely solely on encryption to force payment—they now publish victim data, creating dual pressure for ransom payments
  • Critical infrastructure targeting: Attacks against state-level services increasingly affect essential services like healthcare, utilities, and voting systems

  • This escalating threat landscape puts states in a difficult position: they need sophisticated defensive capabilities and rapid incident response capabilities, yet their budgets and staffing are contracting rather than expanding.


    ## Background and Context: How Federal Support Collapsed


    The relationship between the federal government and state cybersecurity has historically been built on shared responsibility and federal support programs. Two critical federal mechanisms have traditionally provided this support:


    1. The Cybersecurity and Infrastructure Security Agency (CISA): The federal agency responsible for cybersecurity defense and infrastructure protection

    2. Information Sharing and Analysis Centers (ISACs): Public-private partnerships designed to share threat intelligence and best practices


    The Multi-State Information Sharing and Analysis Center (MS-ISAC) emerged as a key mechanism for states to share threat intelligence, compare notes on attacks, and coordinate defensive responses. For years, MS-ISAC operated on a free or heavily subsidized model, making participation accessible to all 50 states regardless of budget constraints.


    However, the funding landscape has shifted dramatically:


    Over the past year, the federal government has downsized CISA's staff, resources, and overall funding allocation. Simultaneously, MS-ISAC has transitioned from a free service to a subscription-based model. This structural change places states in a untenable position: they must now pay for threat intelligence and coordination services that were previously available at minimal cost. For resource-constrained state governments, particularly those in rural or economically disadvantaged regions, this creates a two-tiered cybersecurity landscape where wealth determines access to critical intelligence.


    ## The Federal Partnership Crisis


    Colin Ahern, New York's director of security and intelligence, delivered perhaps the most pointed testimony at the hearing, characterizing the situation as "urgent" and directly appealing to federal lawmakers: "to be a partner to all 50 states." This language reflects deep frustration among state cybersecurity leaders who feel abandoned by the federal government at a critical moment.


    The specific funding concerns states raised:


    | Program | Status | Impact |

    |---------|--------|--------|

    | CISA Staffing & Resources | Downsized | Reduced federal support, slower response times |

    | MS-ISAC Service Model | Subscription Fee | Barrier to participation for underfunded states |

    | State & Local Cybersecurity Grant Program (SLCGP) | Not reauthorized | No dedicated funding stream for state initiatives |

    | Threat Intelligence Sharing | Reduced | States have fewer federal insights into emerging threats |


    Kristin Darby, a chief informational witness at the hearing, emphasized the need for Congress to reauthorize and enhance the State and Local Cybersecurity Grant Program (SLCGP), which provides direct funding for state-level cybersecurity initiatives. Without this funding stream, states must choose between competing budget priorities, and cybersecurity often loses to more visible immediate needs like schools, roads, and emergency services.


    ## Technical and Organizational Implications


    The shift away from federal support creates cascading problems for state cybersecurity operations:


    Staffing Challenges: State governments cannot compete with private sector salaries. Federal funding and grants have traditionally offset this disadvantage by providing dedicated cybersecurity program funding. With that support removed, states must either reduce staff or reallocate other resources.


    Technology Gaps: Defending modern infrastructure requires expensive tools—security information and event management (SIEM) systems, threat intelligence platforms, endpoint detection and response (EDR) solutions. Federal funding has traditionally helped states purchase these tools. Without it, many states will operate with outdated or missing capabilities.


    Information Disadvantage: MS-ISAC's transition to subscription pricing means that states unable to pay may lose visibility into threat intelligence. This creates a dangerous situation where states lack awareness of active threats targeting their peers.


    Coordination Breakdown: When MS-ISAC operated as a free service, all states participated in a common information-sharing network. The subscription model threatens to fragment this network, reducing the collective intelligence available to all participants.


    ## Congressional Response and Path Forward


    The House Homeland Security Subcommittee hearing was not purely academic—state leaders came with specific legislative asks. Congress should consider immediate action on several fronts:


    1. Restore CISA funding and reverse the staffing cuts that have weakened federal cybersecurity leadership

    2. Reauthorize the State and Local Cybersecurity Grant Program with increased appropriations to reflect the current threat environment

    3. Subsidize or restore free access to MS-ISAC to ensure all states can participate in threat intelligence sharing

    4. Establish baseline cybersecurity standards for critical state infrastructure, with federal support to help achieve compliance


    These are not politically partisan issues—cybersecurity threats do not discriminate by party affiliation. Both Democratic and Republican state leaders testified at the hearing, united in their frustration with federal disinvestment.


    ## HackWire Analysis


    This crisis represents a fundamental failure of federal-state partnership at precisely the moment when coordination matters most. Here's what makes this moment different from prior budget debates:


    The timing is catastrophic. Ransomware gangs and state-sponsored threat actors are actively targeting U.S. state infrastructure. The 2024-2026 period has seen coordinated attacks on voting systems, healthcare networks, and utility providers. Federal budget cuts in this environment don't just save money—they actively increase national risk. When states cannot afford to participate in threat intelligence sharing, the nation loses visibility into active campaigns.


    The subscription-model shift breaks a critical trust relationship. MS-ISAC's transition to paid access isn't merely a funding mechanism—it transforms what was a collective good (all states benefiting equally from shared intelligence) into a tiered service (wealthy states get better intelligence than poor ones). This is particularly dangerous because adversaries will naturally concentrate attacks against the least-defended targets. A fragmented, unequally resourced state cybersecurity landscape creates gaps that sophisticated attackers will exploit.


    This mirrors past infrastructure underinvestment. The pattern is disturbingly familiar: federal government underfunds critical infrastructure, attacks increase, citizens suffer, crisis response becomes necessary at much higher cost. We've seen this movie before with physical infrastructure. Cybersecurity should not follow the same plot.


    What states need from Congress is straightforward: treat cybersecurity as the critical national priority it is. That means full funding for CISA, reauthorization and expansion of the SLCGP, and ensuring MS-ISAC remains a true public good accessible to all states regardless of budget constraints. The alternative—a patchwork of well-defended wealthy states and vulnerable underfunded states—serves no one except the threat actors.


    — HackWire Editorial


    ## Recommendations for Organizations


    While waiting for federal action, state governments and critical infrastructure providers should:


  • Conduct threat assessments to identify which MS-ISAC services are most critical and prioritize subscription investment accordingly
  • Strengthen peer-to-peer intelligence sharing within regions to compensate for potential fragmentation of the national ISAC network
  • Invest in automated threat detection to reduce dependence on staffing that may not be sustainable under current budget models
  • Prepare contingency plans for operations without federal support, including partnerships with neighboring states

  • ---


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)